store[.]workshopskinsubscribe[.]com
“Steam Workshop::AUG | Poseidon v1”
store.workshopskinsubscribe.com — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Counter-strike; घोटाले का प्रकार: Gaming Scam. साक्ष्य सारांश: VirusTotal 12/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. रजिस्ट्रार: Web Commerce Communica….
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of the domain store.workshopskinsubscribe.com indicates a brand‑impersonation campaign targeting the Counter‑Strike community. The domain was registered on 5 November 2025 through Web Commerce Communications Limited and resolves to the IPv6 address 2606:4700:3030::6815:49b6, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. Both authoritative name servers, lara.ns.cloudflare.com and sam.ns.cloudflare.com, are Cloudflare‑provided, confirming the use of the provider’s DNS infrastructure. No SSL certificate is presented for the site, and the service is currently reported as offline, preventing retrieval of HTTP status codes or page content beyond the observed page title “Steam Workshop::AUG | Poseidon v1”.
The page title suggests a gaming‑related lure, consistent with the classified scam type “Gaming Scam” and the declared brand target “counter‑strike”. Reputation signals are strongly negative. Gridinsoft assigns a trust score of 0 / 100, and VirusTotal records twelve detections out of ninety‑five scanned engines, indicating that a minority of AV products have identified malicious behavior. The domain appears on a single public blocklist and is explicitly blocked by PhishDestroy, providing additional defensive coverage.
The combination of a newly created domain, Cloudflare hosting, lack of TLS, and the observed page title points to a short‑lived infrastructure designed to mimic legitimate Steam Workshop content and harvest credentials or deliver malware to users seeking Counter‑Strike assets. Uncertainty remains regarding the exact payload or credential‑harvesting mechanism because the site is offline and no further forensic artefacts have been captured.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
Registration: workshopskinsubscribe.com
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For the registrable domain workshopskinsubscribe.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।